Data Processing Addendum
Last updated: 23 August 2026
This Data Processing Addendum ("DPA") forms part of the Terms of Service between Kayalog Innovations Private Limited ("Kayalog", "Processor") and the business or practitioner using our products ("Customer", "Data Fiduciary"). It applies whenever we process personal data on the Customer's behalf.
It is written in line with the Digital Personal Data Protection Act, 2023 (the "DPDP Act"). Where this DPA conflicts with the Terms of Service on a data protection matter, this DPA prevails.
Need a signed copy on your letterhead or ours? Email hello@kayalog.co.in and we will arrange it.
1. Roles
The Customer is the Data Fiduciary. Kayalog is the Data Processor. The Customer decides what personal data is collected, from whom, and for what purpose. Kayalog processes it only to provide the products, and only on the Customer's documented instructions — which include the Customer's ordinary use of the product's features.
2. Scope of processing
| Subject matter | Provision of the Kayalog products subscribed to by the Customer |
|---|---|
| Duration | The term of the Customer's account, plus the retention periods in our Privacy Policy |
| Nature and purpose | Hosting, storage, retrieval, display, transmission and deletion of Customer Data, so the Customer can run its practice or business |
| Types of personal data | Names, contact numbers, email addresses, appointment details, physiotherapy assessments, treatment plans and progress notes, and — where the Customer enables messaging — message content and delivery data |
| Categories of data principals | The Customer's patients and customers, and the Customer's own staff users |
3. Kayalog's obligations
- Process personal data only on the Customer's instructions, and not for our own purposes
- Not sell personal data, and not use it for our own marketing
- Not use Customer Data to train artificial intelligence models
- Keep each Customer's data logically separated from every other Customer's
- Ensure personnel with access are bound by confidentiality
- Implement and maintain the security measures described in section 5
- Assist the Customer, so far as reasonable, with data principal requests and with security or breach obligations
4. Customer's obligations
- Ensure it has a lawful basis, and has given any notice the DPDP Act requires, for every person whose data it records
- Give only lawful instructions, and not require processing that would breach the DPDP Act
- Decide what data to collect and how long to retain it, using the controls in the product
- Keep its user accounts and credentials secure, and remove access when staff leave
- Where messaging is enabled, obtain and record valid consent from every recipient before messaging them
5. Security measures
- Encryption of data in transit and at rest
- Role-based access control, so users see only what their role requires
- Logical separation of each Customer's data
- Restricted, authenticated access to production systems
- Regular backups, held under the same protections as live data
- Logging of access to production systems
We may update these measures over time, provided we do not materially reduce the level of protection.
6. Sub-processors
The Customer authorises Kayalog to engage the sub-processors listed at kayalog.co.in/sub-processors. We impose data protection obligations on each of them no less protective than this DPA, and we remain responsible to the Customer for their performance.
We will update that page before a new sub-processor begins processing Customer Data, and notify affected Customers of material changes. If the Customer has a reasonable objection to a new sub-processor, it may raise it with us; if we cannot resolve it, the Customer may terminate the affected service.
7. Data principal requests
If we receive a request from a patient or end customer to access, correct, or delete their data, we will not respond to it directly. We will forward it to the Customer without undue delay, and assist the Customer in responding using the tools available in the product.
8. Personal data breach
- We will notify the Customer without undue delay after becoming aware of a personal data breach affecting the Customer's data
- Our notice will describe what we know about the nature of the breach, the data affected, the likely consequences, and the steps taken
- We will cooperate with the Customer in meeting its own reporting obligations to the Data Protection Board of India and to affected individuals
9. Location and transfers
Customer Data is hosted in India, in Google Cloud's Mumbai region (asia-south1). Certain sub-processors may process limited data outside India in order to deliver their service, as identified on our sub-processors page. Where that happens, we transfer only what is necessary.
10. Return and deletion
On termination of the Customer's account, the Customer may export its data for 30 days. After that we delete Customer Data in line with the retention periods in our Privacy Policy, except where we are required by Indian law to retain it — for example, invoices and tax records. Data may persist briefly in encrypted backups until they rotate out, and is not restored into the product.
11. Audit
On reasonable written request, and no more than once a year unless required by a regulator, we will provide the information reasonably necessary to demonstrate our compliance with this DPA. Where the Customer requires more, the parties will agree a scope, timing and cost in advance, and the Customer will bear the reasonable cost.
12. Liability
The limitations of liability in the Terms of Service apply to this DPA.
13. Governing law
This DPA is governed by the laws of India. The courts at Jaipur, Rajasthan shall have exclusive jurisdiction.
Contact
Kayalog Innovations Private Limited
CIN: U58200RJ2026PTC113628
Registered office: E 476, Lalkothi Scheme, Behind Vidhan Sabha, Jaipur 302015, Rajasthan, India
Grievance Officer: Kishan Maheshwari — grievance@kayalog.co.in